首页> 外文期刊>Computer standards & interfaces >Mobile cloud security: An adversary model for lightweight browser security
【24h】

Mobile cloud security: An adversary model for lightweight browser security

机译:移动云安全性:轻量级浏览器安全性的对手模型

获取原文
获取原文并翻译 | 示例

摘要

Lightweight browsers on mobile devices are increasingly been used to access cloud services and upload / view data stored on the cloud, due to their faster resource loading capabilities. These browsers use client side efficiency measures such as larger cache storage and fewer plugins. However, the impact on data security of such measures is an understudied area. In this paper, we propose an adversary model to examine the security of lightweight browsers. Using the adversary model, we reveal previously unpublished vulnerabilities in four popular light browsers, namely: UC Browser, Dolphin, CM Browser, and Samsung Stock Browser, which allows an attacker to obtain unauthorized access to the user's private data. The latter include browser history, email content, and bank account details. For example, we also demonstrate that it is possible to replace the images of the cache in one of the browsers, which can be used to facilitate phishing and other fraudulent activities. By identifying the design flaw in these browsers (i.e. improper file storage), we hope that future browser designers can avoid similar errors.
机译:由于移动设备上的轻量级浏览器具有更快的资源加载功能,因此越来越多地用于访问云服务和上载/查看存储在云中的数据。这些浏览器使用客户端效率措施,例如更大的缓存存储和更少的插件。但是,此类措施对数据安全的影响尚待研究。在本文中,我们提出了一个对手模型来检查轻量级浏览器的安全性。使用对手模型,我们在四个流行的轻型浏览器(UC浏览器,Dolphin,CM浏览器和Samsung Stock浏览器)中揭示了先前未发布的漏洞,攻击者可以利用这些漏洞未经授权地访问用户的私人数据。后者包括浏览器历史记录,电子邮件内容和银行帐户详细信息。例如,我们还演示了可以在其中一个浏览器中替换缓存的图像,这可以用于促进网络钓鱼和其他欺诈性活动。通过确定这些浏览器中的设计缺陷(即文件存储不正确),我们希望未来的浏览器设计者可以避免类似的错误。

著录项

  • 来源
    《Computer standards & interfaces》 |2017年第1期|71-78|共8页
  • 作者单位

    School of Information Technology & Mathematical Sciences, University of South Australia, GPO Box 2471, Adelaide, SA 5001, Australia;

    Department of Information Systems and Cyber Security, University of Texas at San Antonio, One UTSA Circle, San Antonio, TX 78249-0631, USA,School of Information Technology & Mathematical Sciences, University of South Australia, GPO Box 2471, Adelaide, SA 5001, Australia;

    School of Information Technology & Mathematical Sciences, University of South Australia, GPO Box 2471, Adelaide, SA 5001, Australia;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Mobile cloud security; Lightweight browser security; UC Browser; Dolphin; CM Browser; Samsung Stock Browser;

    机译:移动云安全;轻巧的浏览器安全性;UC浏览器;海豚;CM浏览器;三星股票浏览器;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号